Files
splunk-security_content/lookups/csv/privileged_azure_ad_roles.csv

5.8 KiB

1azureadroleazuretemplateidisprvilegedadroledescription
2*Application Administrator**9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3*TRUECan create and manage all aspects of app registrations and enterprise apps.
3*Application Developer**cf1c38e5-3621-4004-a7cb-879624dced7c*TRUECan create application registrations independent of the Users can register applications setting.
4*Authentication Administrator**c4e39bd9-1100-46d3-8c65-fb160da0071f*TRUECan access to view, set and reset authentication method information for any non-admin user.
5*Authentication Extensibility Administrator**25a516ed-2fa0-40ea-a2d0-12923a21473a*TRUECustomize sign in and sign up experiences for users by creating and managing custom authentication extensions.
6*Authentication Policy Administrator**526716b-113d-4c15-b2c8-68e3c22b9f80*TRUECan create and manage the authentication methods policy, tenant-wide MFA settings, password protection policy, and verifiable credentials.
7*Azure AD Joined Device Local Administrator**9f06204d-73c1-4d4c-880a-6edb90606fd8*TRUEUsers assigned to this role are added to the local administrators group on Azure AD-joined devices.
8*Azure DevOps Administrator**e3973bdf-4987-49ae-837a-ba8e231c7286*TRUECan manage Azure DevOps policies and settings.
9*Azure Information Protection Administrator**7495fdc4-34c4-4d15-a289-98788ce399fd*TRUECan manage all aspects of the Azure Information Protection product.
10*B2C IEF Keyset Administrator**aaf43236-0c0d-4d5f-883a-6955382ac081*TRUECan manage secrets for federation and encryption in the Identity Experience Framework (IEF).
11*Cloud Application Administrator**158c047a-c907-4556-b7ef-446551a6b5f7*TRUECan create and manage all aspects of app registrations and enterprise apps except App Proxy.
12*Cloud Device Administrator**7698a772-787b-4ac8-901f-60d6b08affd2*TRUELimited access to manage devices in Azure AD.
13*Compliance Administrator**17315797-102d-40b4-93e0-432062caca18*TRUECan read and manage compliance configuration and reports in Azure AD and Microsoft 365.
14*Conditional Access Administrator**b1be1c3e-b65d-4f19-8427-f6fa0d97feb9*TRUECan manage Conditional Access capabilities.
15*Directory Synchronization Accounts**d29b2b05-8046-44ba-8758-1e26182fcf32*TRUEOnly used by Microsoft Entra Connect service.
16*Directory Writers**9360feb5-f418-4baa-8175-e2a00bac4301*TRUECan read and write basic directory information. For granting access to applications, not intended for users.
17*Domain Name Administrator**8329153b-31d0-4727-b945-745eb3bc5f31*TRUECan manage domain names in cloud and on-premises.
18*Exchange Administrator**29232cdf-9323-42fd-ade2-1d097af3e4de*TRUECan manage all aspects of the Exchange product.
19*External Identity Provider Administrator**be2f45a1-457d-42af-a067-6ec1fa63bc45*TRUECan configure identity providers for use in direct federation.
20*Global Administrator**62e90394-69f5-4237-9190-012177145e10*TRUECan manage all aspects of Microsoft Entra ID and Microsoft services that use Microsoft Entra identities.
21*Global Reader**f2ef992c-3afb-46b9-b7cf-a126ee74c451*TRUECan read everything that a Global Administrator can, but not update anything.
22*Groups Administrator**fdd7a751-b60b-444a-984c-02652fe8fa1c*TRUEMembers of this role can create/manage groups, create/manage groups settings like naming and expiration policies, and view groups activity and audit reports.
23*Helpdesk Administrator**729827e3-9c14-49f7-bb1b-9608f156bbb8*TRUECan reset passwords for non-administrators and Helpdesk Administrators.
24*Hybrid Identity Administrator**8ac3fc64-6eca-42ea-9e69-59f4c7b60eb2*TRUECan manage AD to Azure AD cloud provisioning, Azure AD Connect, Pass-through Authentication (PTA), Password hash synchronization (PHS), Seamless Single sign-on (Seamless SSO), and federation settings.
25*Intune Administrator**3a2c62db-5318-420d-8d74-23affee5d9d5*TRUECan manage all aspects of the Intune product.
26*License Administrator**4d6ac14f-3453-41d0-bef9-a3e0c569773a*TRUECan manage product licenses on users and groups.
27*Network Administrator**d37c8bed-0711-4417-ba38-b4abe66ce4c2*TRUECan manage network locations and review enterprise network design insights for Microsoft 365 Software as a Service applications.
28*Partner Tier1 Support**4ba39ca4-527c-499a-b93d-d9b492c50246*TRUEDo not use - not intended for general use
29*Partner Tier2 Support**e00e864a-17c5-4a4b-9c06-f5b95a8d5bd8*TRUEDo not use - not intended for general use
30*Password Administrator**966707d0-3269-4727-9be2-8c3a10f19b9d*TRUECan reset passwords for non-administrators and Password Administrators.
31*Privileged Authentication Administrator**7be44c8a-adaf-4e2a-84d6-ab2649e08a13*TRUECan access to view, set and reset authentication method information for any user (admin or non-admin)
32*Privileged Role Administrator**e8611ab8-c189-46e8-94e1-60213ab1f814*TRUECan manage role assignments in Azure AD, and all aspects of Privileged Identity Management.
33*Security Administrator**194ae4cb-b126-40b2-bd5b-6091b380977d*TRUECan read security information and reports, and manage configuration in Azure AD and Office 365.
34*Security Operator**5f2222b1-57c3-48ba-8ad5-d4759f1fde6f*TRUECreates and manages security events
35*Security Reader**5d6b6bb7-de71-4623-b4af-96380a352509*TRUECan read security information and reports in Microsoft Entra ID and Office 365.
36*SharePoint Administrator**f28a1f50-f6e7-4571-818b-6a12f2af6b6c*TRUECan manage all aspects of the SharePoint service.
37*Teams Administrator**69091246-20e8-4a56-aa4d-066075b2a7a8*TRUECan manage the Microsoft Teams service.
38*User Administrator**fe930be7-5e62-47db-91af-98c3a49a38b1*TRUECan manage all aspects of users and groups, including resetting passwords for limited admins.
39*Windows 365 Administrator**11451d60-acb2-45eb-a7d6-43d0f0125c13*TRUECan provision and manage all aspects of Cloud PCs.